
A hacker claims to have breached the backend servers belonging to an American cybersecurity company and stolen information from the company's "data leak detection" service.
According to the hacker, the stolen data includes more than 8,200 databases containing information on billions of users and has been leaked by other companies during previous security breaches.
The databases were stored on DataViper , a data leak monitoring service run by Vinny Troia, the security researcher who founded the US-based cybersecurity firm Night Lion Security
Data breach monitoring is one of the most common services provided by a cybersecurity company. companies scan the dark web, hacking forums, paste sites, and other places to collect information about data breaches of other companies.
They aggregate “breach databases” on private backends and allow customers to search the data and track when credentials online and when companies themselves suffer a security breach.
The DataViper service breach
A while ago, a hacker named NightLion (the name of Troia's company) sent an email to dozens of cybersecurity journalists that contained a link to a dark web portal containing information about the hack of the cybersecurity company.
The site details the hack into DataViper's backend servers. The hacker claims to have spent three months on DataViper's servers stealing databases that Troia had on the data leak monitoring service.
The hacker published 8,225 databases from the DataViper service, a list of 482 files JSON containing samples of the data stolen from the servers, and provided evidence of access to the DataViper backend.
Additionally, the hacker posted ads on the Empire dark web marketplace, offering for sale 50 of the largest databases found on DataViper's backend servers.

Most of the 8,200+ databases listed by the hackerwere “old leaks” that came from breaches that occurred years ago.
Troia: Hacker breached test server
Troia admitted that the attacker gained access to one of DataViper's servers. However, the founder of Night Lion Security said that it was a test server.
Troia believes the hacker is actually selling his own databases, not information he stole from the cybersecurity company.
The security researcher said that this data has been publicly available for many years. In some cases, Troia gained access to it from the same hacking communities that the hacker himself belongs to.
Troia believes the hacker is associated with various hacking groups, including TheDarkOverlord, ShinyHunters, and GnosticPlayers.
All groups have extensive hacking histories and are responsible for hundreds of breaches.
The DataViper founder says the current leak was intended to damage his reputation ahead of a keynote he was scheduled to give Wednesday at the SecureWorld security conference. In his speech, he was expected to mention many of these hacking groups.
